plugin

Woocommerce Subscriptions Vulnerabilities

14 known security issues reported for the Woocommerce Subscriptions WordPress plugin. Most recent disclosed Aug 14, 2026.

1 high 5 medium

Running Woocommerce Subscriptions on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Subscription < 9.1.0 - Unauthenticated PHP Object Injection

medium

The WooCommerce Subscription plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 9.1.0 (exclusive) via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this...

CVSS:
5.3
Affected:
up to 9.1.0
Fixed in:
9.1.0
Disclosed:
Aug 14, 2026

CVE-2026-18391 on NVD →

WooCommerce Subscriptions [woocommerce-subscriptions] < 5.8.0

unknown

[en] Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.

Affected:
up to 5.8.0
Fixed in:
5.8.0
Disclosed:
Dec 31, 2024

CVE-2023-50850 on NVD →

WooCommerce Subscriptions < 5.8.0 - Missing Authorization

medium

The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized access of data or modification of data due to a missing capability check on an unknown low-severity function in versions up to 5.8.0. This makes it possible for authenticated attackers, with contributor-level access and above, to make use...

CVSS:
4.3
Affected:
up to 5.8.0
Fixed in:
5.8.0
Disclosed:
Jan 17, 2024

CVE-2023-50850 on NVD →

WooCommerce Subscriptions [woocommerce-subscriptions] < 5.1.3

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.

Affected:
up to 5.1.3
Fixed in:
5.1.3
Disclosed:
Dec 20, 2023

CVE-2023-35914 on NVD →

WooCommerce Subscription < 4.6.0 - Cross-Site Request Forgery

medium

The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...

CVSS:
4.3
Affected:
up to 4.6.0
Fixed in:
4.6.0
Disclosed:
Sep 11, 2023

WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0

unknown

The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...

Affected:
up to 4.6.0
Fixed in:
4.6.0
Disclosed:
Sep 11, 2023

WooCommerce Subscriptions <= 5.1.2 - Missing Authorization to Insecure Direct Object Reference

medium

The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown unction in versions up to, and including, 5.1.2. This makes it possible for unauthenticated attackers to access or modify information by passing in a user-conttrolled par...

CVSS:
6.5
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
Jun 19, 2023

CVE-2023-35914 on NVD →

WooCommerce Subscriptions [woocommerce-subscriptions] < 2.6.3

unknown

[en] Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Jul 23, 2020

CVE-2019-18834 on NVD →

WooCommerce Subscriptions <= 3.0.2 - Cross-Site Request Forgery

high

The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to incorrect nonce validation on the view-subscription functionality. This makes it possible for unauthenticated attackers to modify any user's subscription status via a fo...

CVSS:
8.3
Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Apr 2, 2020

WooCommerce Subscriptions [woocommerce-subscriptions] < 3.0.3

unknown

The WooCommerce Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.2. This is due to incorrect nonce validation on the view-subscription functionality. This makes it possible for unauthenticated attackers to modify any user's subscription status via a fo...

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Apr 2, 2020

WooCommerce Subscriptions < 2.6.3 - Stored Cross-Site Scripting

medium

Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

CVSS:
6.1
Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Mar 11, 2019

CVE-2019-18834 on NVD →

WooCommerce Subscriptions [woocommerce-subscriptions] < 3.0.3

unknown

During a blog assessment, we identified a CSRF issue in the Woocommerce Subscriptions plugin, which could allow attackers to cancel and re-activate a logged in user&#039;s subscription. Even though the _wpnonce parameter was needed in the request, its value was not verified, allowing an empty value to be honoured. K...

Affected:
up to 3.0.3
Fixed in:
3.0.3

WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0

unknown

The plugin does not have CSRF check when suspending and activating subscriptions, which could allow attackers to make a logged in admin suspend or activate arbitrary subscription via a CSRF attack

Affected:
up to 4.6.0
Fixed in:
4.6.0

WooCommerce Subscriptions [woocommerce-subscriptions] < 4.6.0

unknown

The WooCommerce Subscription for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and not including, 4.6.0. This is due to missing or incorrect nonce validation when suspending or canceling subscriptions. This makes it possible for unauthenticated attackers to change arbitrary subscriptions via...

Affected:
up to 4.6.0
Fixed in:
4.6.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database